Google Cloud fraud defense, the next evolution of reCAPTCHA
21–30 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#22Earlier quoted context omitted.
... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.
99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#23Earlier quoted context omitted.
The app that scans the code talks to the TPM in your phone to prove that your phone is running an unmodified Google OS.
Which would be meaningful if phones weren't remotely controllable. So the net effect is every AI agent will also have and connect to a physical phone.
And the official Google OS just won't feature remote-control software.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#24Earlier quoted context omitted.
99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.
Yeah, this is going to turn into another malware vector, isn't it?
So does Binance.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#25Earlier quoted context omitted.
The app that scans the code talks to the TPM in your phone to prove that your phone is running an unmodified Google OS.
Which would be meaningful if phones weren't remotely controllable. So the net effect is every AI agent will also have and connect to a physical phone.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#26The fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#27The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.
If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_DEVICE_INTEGRITY is required, that would probably not be explicitly listed here.
E.g. the consumer documentation for Google Pay just says you need a "certified" Android device and a screen lock set up: https://support.google.com/wallet/answer/12200245
(Yes, if you go deep into the FAQ at the end it eventually states that if you rooted your phone, you can't use tap to pay, but that requirement is implied by the certification requirement [1].)
In Google's eyes, and in the eyes of the law due to trademarks filed by Google, Android == Google Android.
This feature would make little sense if it's not using device attestation because otherwise it would be easy to spoof. I expect that it will initially not use it, and they will start A/B testing device attestation in the coming years.
[1] Expand "What to do if you see device is not certified" -> "Reset device to fix issue" https://support.google.com/android/answer/7165974
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#28The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#29Google building harder walls against bots while simultaneously building AI agents that need to get through them is peak 2026.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#30Why can't an AI scan the QR code? Just fire up an emulator if necessary